|
256961
|
7.8 |
HIGH
Local
|
forescout
|
secureconnector
|
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9486
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256962
|
7.8 |
HIGH
Local
|
forescout
|
secureconnector
|
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9485
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256963
|
4.4 |
MEDIUM
Local
|
linux
|
linux_kernel
|
It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2016-9604
|
2024-11-21 12:01 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256964
|
8.8 |
HIGH
Network
|
redhat debian mozilla
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux thunderbird firefox_esr
|
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
|
CWE-284
Improper Access Control
|
CVE-2016-9905
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256965
|
7.5 |
HIGH
Network
|
redhat debian mozilla
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux thunderbird firefox firefox_esr
|
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernam…
|
CWE-200
Information Exposure
|
CVE-2016-9904
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256966
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting co…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9903
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256967
|
7.5 |
HIGH
Network
|
redhat mozilla
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_eus firefox firefox_esr
|
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and in…
|
CWE-346
Origin Validation Error
|
CVE-2016-9902
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256968
|
9.8 |
CRITICAL
Network
|
redhat mozilla
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_aus enterprise_linux_eus firefox firefox_esr
|
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pock…
|
CWE-20
Improper Input Validation
|
CVE-2016-9901
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256969
|
9.8 |
CRITICAL
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus firefox thu…
|
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird…
|
CWE-416
Use After Free
|
CVE-2016-9899
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256970
|
9.8 |
CRITICAL
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
|
CWE-416
Use After Free
|
CVE-2016-9898
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|